Repository navigation
fix(OMN-15737): admit Dep Provenance Gate into CI Summary EXPECTED_EXTERNAL_CONTEXTS - #2684
jonahgabriel merged 10 commits into
Conversation
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 10 minutes Limit details: You’ve used the included review currently available. Your 116 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?Wait for the limit to reset, then comment An organization admin can change what happens after included review limits in Billing. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
Comment |
|
OCC autobind did not mint a companion for this PR: no changed-file candidate could be proven RED against the merge base, and emitting a PR-existence probe instead would be non-falsifiable evidence (OMN-15247). Hand-authored evidence is required. |
#6198) * evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2684 * evidence: OCC companion self-bind for #6198 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
…TERNAL_CONTEXTS OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own DoD item "required on infra dev/main branch protection" was never fulfilled live: the context reports on every PR (no job-level `if:`) but blocks nothing on dev or main today. Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16 green over the last 16 merged omnibase_infra dev PRs (#2646-#2669, 2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified against the SAME #2546-#2567 golden-fixture window already pinned by test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree, so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing fixture rows, closing it fail-closed on dev via the sole required `CI Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection API mutation in this PR). Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix (scripts/sync-node-migrations.sh output) that was already red on dev HEAD before this change and blocked the pre-commit gate for this PR (no-pre-existing-excuse policy).
The previous commit's json.dump reformatted the whole fixture file (2-space indent vs the file's original 1-space convention), producing an 8000-line diff noise. Re-dump with indent=1 to match the existing style; diff is now scoped to the actual added rows.
…anifest test_application_migration_manifest.py caught what the bundled vendor-sync fix (previous commit) missed: adding node_canary_score_reducer/0003 and node_projection_registration/0004 to the vendor tree without a matching declaration in docker/migrations/forward/_ledger/application-migrations.tsv left the manifest incomplete (94 declared vs 96 on disk). Domain classification follows the established, already-committed pattern for each node rather than inventing new policy: - node_canary_score_reducer/0003 (capability_scores tenant_id TEXT->UUID): domain=tenant, continuing sibling 0002's tenant domain for the same already-tenant-classified column. - node_projection_registration/0004 (node_service_registry NO FORCE RLS): domain=omninode_internal, matching the file's own inline OMN-15336 item-4 domain corroboration (contract.yaml db_io.schema=omninode_internal, 2026-08-02 operator ruling, OMN-15656 grants-derivation correction). Full impacted suite (scripts/ci/tests, scripts/tests, tests/ci, tests/scripts, tests/unit/scripts) re-run green: 3011 passed, 5 skipped.
…dev rebase The OMN-15732 deadlock-fix rebase auto-merged two intermediate commits' TSV additions for node_canary_score_reducer/0003 and node_projection_registration/0004 with stale checksums, alongside dev's already-correct rows for the same files (dev holds the adjudicated single-file 0003 since 211e81e). Take dev's TSV wholesale -- this PR has no legitimate TSV diff of its own.
b87a344 to
6d52d35
Compare
✅ Hostile Reviewer — PASSEDBlocking findings (critical): 0 Gate semantics (pilot phase)
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524) |
…Dep Provenance Gate + Integration Test Removal Gate EXPECTED_EXTERNAL_CONTEXTS entries; backfill fixture rows
OMN-15737
OMN-13873 (Done) shipped
Dep Provenance Gate(dep-provenance-gate.yml, jobdep-provenance-gate) but its own DoD item "Gate workflow present and required on infra dev/main branch protection" was never fulfilled live. Live readback today:omnibase_infradevrequired_status_checks:["CI Summary"]only —Dep Provenance Gateabsentomnibase_inframainrequired_status_checks: 5-context set, also absentscripts/ci/ci_summary_gate.py'sEXPECTED_EXTERNAL_CONTEXTS(the OMN-15496 mechanism that fail-closed-asserts cross-workflow contexts through the sole requiredCI Summaryumbrella) did not include itSo the gate runs on every PR (no job-level
if:— it always executes and reports) but currently blocks nothing on dev or main.Measurement (per the file's own admission rule)
16/16 merged
omnibase_infradev PRs (#2646–#2669, 2026-08-04T16:56Z → 2026-08-07T01:08Z),started_at <= mergedAt:16/16 present, 16/16 green.
Cross-checked against the SAME #2546–#2567 golden-fixture window
test_no_wedge_replay_over_sixteen_merged_dev_prsalready pins:16/16 present, 16/16 green (also folded into
tests/ci/fixtures/omn15496_merge_time_external_check_runs.json).Both independent 16-PR windows agree — qualifies cleanly under the admission rule.
Fix
Add
"Dep Provenance Gate"toEXPECTED_EXTERNAL_CONTEXTSinscripts/ci/ci_summary_gate.py. Closes the gap fail-closed ondevvia the existingCI Summaryumbrella — the code path per CLAUDE.md rule 10, no branch-protection API mutation in this PR. Adding it tomain's direct required_status_checks is a separate branch-protection mutation left for the operator.Incidental fix bundled (pre-existing, unrelated to the above)
scripts/sync-node-migrations.sh --check(always_run: truepre-commit hook) was already red onorigin/devHEAD before this change — 2 omnimarket node migrations (node_canary_score_reducer/0003_capability_scores_tenant_id_to_uuid.sql,node_projection_registration/0004_node_service_registry_no_force_rls.sql) existed upstream but were never vendored intodocker/migrations/forward/nodes/. Since this hook blocks any commit to the repo regardless of diff content, it had to be fixed to land this PR at all (no-pre-existing-excuse policy). Vendored both files and declared them indocker/migrations/forward/_ledger/application-migrations.tsvfollowing the established pattern for each node (not new policy):node_canary_score_reducer/0003: domain=tenant, continuing sibling 0002's tenant domain for the same already-tenant-classified column.node_projection_registration/0004: domain=omninode_internal, matching the file's own inline OMN-15336 item-4 domain corroboration.test_application_migration_manifest.py's pinned declaration count updated 94 → 96 accordingly.Verification
tests/ci/test_ci_summary_gate.py: 52 passedtests/unit/scripts/validation/test_application_migration_manifest.py: 8 passedscripts/ci/tests/ scripts/tests/ tests/ci/ tests/scripts/ tests/unit/scripts/,--ignore=tests/integration): 3011 passed, 5 skippedZero AWS/prod mutation. Zero branch-protection API mutation.
Evidence-Ticket: OMN-15737
Evidence-Source: OCC#6198